splunk-sdk does not properly verify untrusted TLS server certificates
Critical severity
GitHub Reviewed
Published
Mar 25, 2019
to the GitHub Advisory Database
•
Updated Oct 27, 2024
Description
Published to the GitHub Advisory Database
Mar 25, 2019
Reviewed
Jun 16, 2020
Last updated
Oct 27, 2024
Splunk-SDK-Python before 1.6.6 does not properly verify untrusted TLS server certificates, which could result in man-in-the-middle attacks.
References